Auto Subpage Menu Security & Risk Analysis

wordpress.org/plugins/auto-subpage-menu

By default wordpress menu system, wordpress can only automatically add/remove top-level page to/from menus

900 active installs v1.1.5 PHP + WP 3.3.0+ Updated Aug 4, 2020
adminchild-pagemenumenusnavigation
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Auto Subpage Menu Safe to Use in 2026?

Generally Safe

Score 85/100

Auto Subpage Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The static analysis of "auto-subpage-menu" v1.1.5 reveals a strong security posture with no identified critical vulnerabilities in the analyzed code. The absence of dangerous functions, file operations, external HTTP requests, and the proper use of prepared statements for its single SQL query are all positive indicators. Furthermore, all identified outputs are properly escaped, and there are no taint flows with unsanitized paths, suggesting robust data handling practices within the plugin's current code. The vulnerability history is also clear, with no recorded CVEs, indicating a historically safe plugin.

However, the most significant concern arises from the complete lack of any observed entry points, such as AJAX handlers, REST API routes, shortcodes, or cron events. While this might seem like a strength, it could also indicate that the plugin has no user-facing functionality or is not actively interacting with WordPress in a way that would trigger these entry points. More critically, the absence of any capability checks or nonce checks across any potential entry points (even though none were explicitly found) is a significant oversight. If any entry points were to be introduced or if the analysis missed any subtle interaction points, the lack of these fundamental WordPress security mechanisms would leave the plugin highly vulnerable to privilege escalation or unauthorized actions.

Key Concerns

  • No capability checks found
  • No nonce checks found
Vulnerabilities
None known

Auto Subpage Menu Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Auto Subpage Menu Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries
Attack Surface

Auto Subpage Menu Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionpost_updatedauto-subpage-menu.php:16
actionwp_trash_postauto-subpage-menu.php:17
Maintenance & Trust

Auto Subpage Menu Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedAug 4, 2020
PHP min version
Downloads10K

Community Trust

Rating86/100
Number of ratings12
Active installs900
Developer Profile

Auto Subpage Menu Developer Profile

jojoee

6 plugins · 2K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Auto Subpage Menu

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Auto Subpage Menu